CVE-2026-73576CWE-1241

CVE-2026-73576

Medium · published August 13, 2026

CVSS v3.1
6.3
EPSS
0%
Percentile
9.1
In the wild
Unconfirmed
What it is

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

The record
Technical detail
CVSS v3.1
6.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00194 · 9.1th percentile
Weakness
CWE-1241 · Use of Predictable Algorithm in Random Number Generator
Published
2026-08-13T20:19Z
Affected products (1)
ProductVersionsFixed in
synacor/zimbra_collaboration_suite< 10.1.1710.1.17
References (2)
EPSS history
Timeline
  • 13 AUG 15:26Z
    In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration
    cvelistv5